London hosts the head offices of insurers, payment providers, publishers, industrial groups, and consumer brands, each operating under a regulatory environment shaped by GDPR, NIS2, FCA supervision, and the UK’s evolving cyber resilience legislation. The security leaders below have built programmes in private banking, defence and intelligence, global manufacturing, and the NHS supply chain. Several arrived at the CISO seat from adjacent disciplines, and several have carried regulatory accountability in their own names.
Kate Silverman – CISO, Rightmove
Kate Silverman joined Rightmove as CISO in August 2026, bringing more than fifteen years across technology and security in multiple industries. She arrived from Ardagh Group, the global packaging manufacturer, where she served as Global Deputy CISO for two years and before that as Group Cyber Director covering security architecture, privacy, and third party assurance. She also held the Chief Technology Officer post there on an interim basis, an unusual crossover that put her accountable for the estate as well as its protection. Her earlier work was in security design. Moving from heavy manufacturing to the UK’s largest property portal is a considerable shift in threat model, from industrial operations to a consumer platform handling millions of user records, and the architecture and third party assurance background travels directly.
Fadi Serhan – CISO, Everway
Fadi Serhan leads security strategy across Everway, a role he took in October 2025, with a focus on governance, risk management, and business enablement. He brings more than fifteen years building and leading global security programmes spanning application security, cloud security, security operations, and GRC. Most recently he ran security engineering at Beamery, where he was first hired as lead security engineer to build the function and stayed to scale it, partnering with the CISO, CTO, product, and legal teams to enable secure product development across an engineering organisation of more than a hundred. His stated priority is making security measurable, transparent, and collaborative, using the right mix of governance, automation, and culture rather than leaning on any one of them.
Jayesh Patel – CISO, Ingenico
Jayesh Patel joined payments technology company Ingenico as CISO in March 2026, bringing more than twenty-five years across information security and data protection. He came from Hays, where he was Director of Information Security and Data Protection, and before that spent nearly five years as Chief Information Security and Data Privacy Officer at Oxford University Press, leading global cyber and data security strategy across risk, threat, and compliance programmes while building audit, assurance, and privacy practices into the publisher’s international operations. Earlier he built the first global cybersecurity and data protection function at Save the Children International from a greenfield start, running both security and data protection for the charity. His background also includes work for leading Fortune 500 financial services corporations, and he holds a master’s in business management alongside industry security certifications.
Nathan Cooper – Global Cyber Security & Compliance Director, Kent
Nathan Cooper joined Kent in July 2026 from Kantar, where he was Head of Cyber Security. His twenty-six years span financial services, defence and intelligence, His Majesty’s Government, healthcare, and consultancy, with advisory work running from niche service providers up to UK Critical National Infrastructure. As UK CISO of EFG Private Bank he worked in an industry defined by client secrecy, running maturity assessments against regulatory requirements, designing cyber improvement plans, and securing resources through board-endorsed strategies. At Vistra Group he was Global Head of Information Security during a period of rapid expansion, defining the security strategy, recruiting a new global team, and taking the business through ISO 27001 certification. He describes his focus as reducing enterprise risk in line with organisational risk appetite, and holds CISSP, CISM, and CISA alongside a BSc and MSc.
Simon Strickland – CISO, Imperial Brands
Simon Strickland has spent his career securing companies that make physical things at enormous scale. CISO of Imperial Brands since April 2024, he previously spent more than six years as CISO of Johnson Matthey, the speciality chemicals group, and before that led enterprise security strategy at Jaguar Land Rover. His first CISO post was at Anglo American, the mining group, and the foundation was three years as Global Head of IT Security at AstraZeneca, where he set, embedded, and implemented the global IT security strategy with a strong focus on business risk management and reporting. Pharmaceuticals, mining, automotive, chemicals, and now tobacco is an unusual run, but the through-line is consistent: multinational operations, industrial technology, and regulators in every jurisdiction the business touches.
Richard Frost – CISO, Ageas UK
Richard Frost leads cyber security strategy and large-scale digital and infrastructure transformation at Ageas UK, one of the country’s leading insurers. A certified C-CISO and CISSP, he is also an FCA-regulated Senior Management Function holder, meaning regulatory accountability sits with him personally rather than diffusely across a committee. He arrived from esure Group, where he led a comprehensive security modernisation following the Bain Capital acquisition, transforming the business into a cloud-native digital insurer and building a cyber maturity narrative to support the group’s strategic exit ambitions. That experience shapes how he frames the role now: partnering with executive leadership and boards to position security as a commercial differentiator and a transformation accelerator rather than a cost centre.
S.I Ndumbe – CISO, GenesisCare UK
S.I Ndumbe leads the cyber security function at GenesisCare UK, appointed in July 2026, with one of the widest stated remits on this list. It spans governance, risk, and compliance across GDPR, NIS2, the UK Cyber Security and Resilience Bill, the Data Protection Act, the Computer Misuse Act, ISO 27001, Cyber Essentials Plus, and NHS DSPT requirements, alongside security operations, architecture, incident response, and third-party risk. He owns the information security strategy and the continual improvement of the ISMS, and provides subject matter expertise across identity and access management, MFA, RBAC, and endpoint, cloud, network, and application security. Incident response, forensic remediation, penetration testing, and AI governance also sit with him. He holds an MSc and is a member of BCS and AEHIS.
What This Group Says About London
London’s security leaders answer to regulators, boards, and customers in equal measure, often across jurisdictions and always under scrutiny. Several here carry personal regulatory accountability, and most have built or rebuilt a function rather than inheriting one: a greenfield programme at a global charity, a first security team at an expanding financial services group, a modernisation run through a private equity acquisition. The capital’s business base rewards that kind of builder, and this is the bench it has produced.
Explore more CISOs to Watch:
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

